PT-2026-40121 · Horovod · Horovod

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-31234

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Horovod versions prior to 0.28.2
Description The KVStore HTTP server component, used for distributed task coordination, lacks authentication and authorization controls. This allows a remote attacker to write arbitrary data using HTTP PUT requests. When a worker reads this data via HTTP GET, it uses the cloudpickle.loads() function to deserialize the data without verifying its source or integrity. An attacker can send a malicious pickle payload to the server, which, when deserialized by the victim worker, leads to remote code execution.
Recommendations Update to version 0.28.2 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31234
GHSA-MF8F-X4R3-JM8C

Affected Products

Horovod